Low severityNVD Advisory· Published Jun 17, 2026
Symlink-following arbitrary write via github_workflows module
CVE-2026-12567
Description
The github_workflows module constructs local directory paths from user-controlled repository names without validating for symlinks. A local attacker sharing the scan directory can plant a symlink at the predictable output path, causing workflow data to be written to an attacker-chosen location.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
bbotPyPI | >= 2.0.0, < 2.8.5 | 2.8.5 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.